Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Motors Theme Vulnerability Exploited to Hack WordPress Websites

Motors Theme Vulnerability Exploited to Hack WordPress Websites

Posted on June 20, 2025June 20, 2025 By CWS

Mass exploitation of a critical-severity vulnerability within the Motors theme for WordPress began a number of weeks after public disclosure, WordPress safety agency Defiant warns.

The Motors theme is geared toward automotive dealership companies, together with automobile, motorbike, boat, and automobile rental sellers, providing pre-built web sites and templates, and help for itemizing, person and supplier administration.

The exploited vulnerability, tracked as CVE-2025-4322 (CVSS rating of 9.8), is described as a privilege escalation concern by way of account takeover.

The bug exists as a result of the theme fails to correctly validate person identities previous to updating account passwords, which permits attackers to vary the password of any person account.

“This makes it doable for unauthenticated attackers to vary arbitrary person passwords, together with these of directors, and leverage that to realize entry to their account,” a NIST advisory reads.

The safety defect was patched on Could 14 and publicly disclosed on Could 19. In accordance with Defiant, the primary exploitation makes an attempt focusing on the bug had been noticed on Could 20, whereas mass exploitation began on June 7.

The WordPress safety agency warns that over 22,000 web sites are utilizing the theme, and that it has blocked greater than 23,000 exploit makes an attempt focusing on CVE-2025-4322 because the vulnerability was publicly disclosed.

The difficulty impacts the theme’s Login Register widget, which incorporates the susceptible password restoration perform. As a result of the perform doesn’t forestall password updates if the hash from the person meta worth is empty, an attacker can replace the person’s password if the person has not requested a password reset.Commercial. Scroll to proceed studying.

Profitable exploitation of the safety defect, Defiant notes, can result in full web site compromise, as it might present attackers with entry to all administrative capabilities.

“This contains the power to add plugin and theme recordsdata, which will be malicious zip recordsdata containing backdoors, and to switch posts and pages which will be leveraged to redirect web site customers to different malicious websites or inject spam content material,” the safety agency explains.

CVE-2025-4322 was resolved in Motors theme model 5.6.68. Customers are suggested to replace to the patched model or a more recent launch as quickly as doable.

Associated: ‘AkiraBot’ Spammed 80,000 Web sites With AI-Generated Messages

Associated: Second OttoKit Vulnerability Exploited to Hack WordPress Websites

Associated: Vulnerability in OttoKit WordPress Plugin Exploited within the Wild

Associated: Risk Actors Deploy WordPress Malware in ‘mu-plugins’ Listing

Security Week News Tags:Exploited, Hack, Motors, Theme, Vulnerability, Websites, WordPress

Post navigation

Previous Post: FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks
Next Post: Godfather Android Trojan Creates Sandbox on Infected Devices

Related Posts

Israeli Cyber Fund Glilot Capital Raises 0 Million Israeli Cyber Fund Glilot Capital Raises $500 Million Security Week News
Adobe Addresses 44 Vulnerabilities in Software Update Adobe Addresses 44 Vulnerabilities in Software Update Security Week News
Zast.AI Secures  Million for Advanced Code Security Zast.AI Secures $6 Million for Advanced Code Security Security Week News
574 Arrested,  Million Seized in Crackdown on African Cybercrime Rings 574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings Security Week News
Novel 5G Attack Bypasses Need for Malicious Base Station Novel 5G Attack Bypasses Need for Malicious Base Station Security Week News
Gabbard Says UK Scraps Demand for Apple to Give Backdoor Access to Data Gabbard Says UK Scraps Demand for Apple to Give Backdoor Access to Data Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News